Briefings

Australian AI Governance Briefing: Week Ending 5 April 2026

Law firms warn the Children's Online Privacy Code will require fundamental changes to online services as industry delivers mixed verdicts on the Anthropic MOU's substance.

9 stories

The week in review

The headline announcements of 1 April — the government’s formal response to the Senate AI inquiry, the Anthropic MOU, the Children’s Online Privacy Code exposure draft, and the Unfair Trading Practices Bill — were covered in last week’s briefing. This week, the real story was what happened next: the legal profession, industry analysts, and affected sectors began digesting those announcements and reaching early conclusions about what they actually mean for Australian organisations.

Law firms deliver first detailed verdicts on the Children’s Online Privacy Code

Corrs Chambers Westgarth published one of the first comprehensive legal analyses of the COPC exposure draft, and the verdict was direct: the Code would represent “a significant shift in the Australian regulatory landscape” for any organisation whose digital products and services involve children’s personal information. Corrs highlighted the Code’s introduction of a novel concept of “assent” for children under 15 — maintaining parental consent as the legal authorisation mechanism while requiring services to involve children in the process in age-appropriate ways. The firm also flagged the Code’s prohibition on coercive consent methods, including “confirmshaming” using guilt-inducing language, as a significant new restriction on how AI-powered services can interact with young users. The bottom line from Corrs: “major technical, operational, process and policy changes would be required to ensure compliance.”

DLA Piper reached a similar conclusion, characterising the Code as signalling “tougher standards” for how organisations handle children’s data. Both firms noted the Code’s alignment with international equivalents, particularly the UK’s Age Appropriate Design Code, while flagging that some of the Australian provisions go further — including requirements to notify children when parents consent to data collection on their behalf, and when other users (including parents) track their geolocation on a service.

Addisons published a detailed walkthrough of the Code’s scope, noting it would capture not only social media platforms but also streaming services, cloud storage providers, and internet-connected devices such as baby monitors. The breadth of coverage means many organisations that do not think of themselves as providing children’s services may nonetheless be captured if their products are “likely to be accessed by children.”

The OAIC itself moved quickly to support the consultation process, hosting a public webinar on 1 April to explain the Code and the submission process. The Commissioner also announced Virtual Roundtables between 31 May and 5 June, and confirmed that the Office will conduct a Regulatory Impact Analysis — a formal cost-benefit assessment — alongside the consultation. These procedural signals matter: the OAIC is investing significant resources in building the evidence base for the Code’s final form, and is actively seeking to engage stakeholders who might otherwise wait until the Code is finalised. With the 60-day consultation closing 5 June 2026 and the Code due for registration by 10 December 2026, the window for influence is relatively narrow.

Anthropic MOU draws a spectrum of industry reactions

The Anthropic MOU attracted reactions ranging from genuinely positive to openly sceptical, with the most substantive analysis focusing on whether the arrangement delivers anything beyond political symbolism.

SmartCompany’s “Neural Notes” column provided perhaps the most thoughtful industry take, identifying Anthropic’s commitment to share its Economic Index data with the Australian government as the MOU’s most distinctive feature. The Economic Index tracks how Claude is used across the economy — by sector, task type, and labour impact — with an initial focus on natural resources, agriculture, healthcare, and financial services. SmartCompany noted this gives government “structured visibility into real AI usage patterns in workplaces” that no prior partnership with OpenAI or Microsoft had offered. However, the analysis cautioned that the Index reflects only Anthropic’s user base, providing “a partial view rather than a complete one” — and that the data may shape how AI’s economic impact is framed depending on which sectors are most visible within Anthropic’s ecosystem.

Startup Daily took a more sceptical approach, running both the government’s and Anthropic’s press releases through Claude itself to compare the framing. The result was revealing: the government version used softer, more tentative language (“outlines options,” “exploring investments”) while Anthropic’s positioning was more confident and definitive. Supply chain security language appeared only in the government release — described by Startup Daily as “the most geopolitically significant line” in either document. The outlet characterised the AUD$3 million research commitment as modest: “like the boss slapping $50 on the pub counter for Christmas drinks.”

Cyber Daily highlighted the copyright politics surrounding the visit. While noting that Anthropic “often paints itself as the most ethical of the AI giants,” the outlet reported that the company has previously critiqued Australia’s copyright legislation. Amodei’s careful statement that he was not there to “try and convince you to change your mind” on copyright was widely read as a diplomatic acknowledgment that copyright reform remains a live political issue the government is not ready to resolve. Notably, AAP reporting from the Parliament House event captured Amodei’s geopolitical framing — warning that AI in the hands of countries with sophisticated surveillance systems could create a “panopticon” and that on the international stage, AI represents a “military competition” where democracies must maintain their edge. These comments came against the backdrop of Anthropic’s ongoing dispute with the US Department of Defense, which has designated the company a supply-chain risk after it refused to allow its technology for mass surveillance.

The Australian Information Industry Association offered measured support, with CEO Elizabeth Whitelock saying “global partnerships are critical, but they must be anchored in national priorities.” University of NSW computer science professor Toby Walsh put it more pointedly: “It won’t be good enough just to ensure that the Anthropic models are safe. You want to make sure that Google, OpenAI and everybody else’s models are safe too.”

The Copyright Agency published an immediate reaction to the government’s formal response to the Senate AI inquiry. The Agency welcomed the government’s confirmation that it is not considering a text and data mining exception in Australian copyright law — a position that puts Australia at odds with many other jurisdictions — and highlighted the three priorities being pursued through the Copyright and AI Reference Group (CAIRG): licensing arrangements for AI use of copyright material, improving certainty on copyright for AI-generated material, and exploring a small claims forum for copyright disputes.

Copyright is emerging as the most politically contested dimension of Australia’s AI governance framework. The government is trying to thread a needle between enabling AI development and protecting the creative sector. The 1 April Senate inquiry response signalled that, at least for now, the government tilts toward protection. The Anthropic MOU signing on the same day added an interesting counterpoint — a major AI company establishing a formal relationship with the government while the copyright question remains unresolved, and while Australia’s arts sector has publicly accused Anthropic and other AI companies of pushing to loosen copyright laws so chatbots can be trained on local creative works.

UTP Bill’s AI dimensions come into sharper focus

Gilbert + Tobin published a detailed analysis of the Competition and Consumer Amendment (Unfair Trading Practices) Bill 2026 following its 1 April introduction in the House of Representatives. The AI-specific implications are significant. G+T confirmed the Bill’s first limb specifically targets “dark patterns” in digital interfaces, defined as conduct that “manipulates a consumer or unreasonably distorts the environment in which a consumer makes, or is likely to make, a decision.” This directly captures AI-driven recommendation systems, personalised pricing algorithms, and automated design manipulation techniques.

Penalties are substantial: up to AU$50 million per contravention for a body corporate (doubled to $100 million once the separately passed penalties bill takes effect). The Bill also signals future expansion — the government has already commenced targeted consultations on extending unfair trading practice protections to small businesses and franchisees, and is working with ASIC on whether “further steps are appropriate in the financial services sector.”

If passed, the Bill would apply from 1 July 2027. The Senate is not scheduled to debate it until 12–14 May 2026. G+T’s analysis makes clear that any business using AI to shape consumer decisions — whether through recommendation engines, dynamic pricing, or subscription management — should be reviewing its practices well before the legislation is finalised.

Government machinery moves from policy to implementation

Beyond the headline announcements, quieter signals suggest the government’s AI governance machinery is transitioning from policy documents to institutional capability. iTnews reported that the Digital Transformation Agency is hiring eight new positions to establish the promised whole-of-government AI oversight committee. Roles include a digital governance and risk expert to set up and manage the committee, and a senior AI policy officer. DTA Acting CEO Lucy Poole confirmed the roles are “a direct response to the government’s policy to establish the committee,” which is scheduled to become operational late 2026.

The government’s formal response to the Senate inquiry also revealed details that received less attention amid the headline coverage. It confirmed an AI Accelerator funding round under the Cooperative Research Centres program — a CRC Projects round in 2026 followed by a full CRC round in 2027 — designed to incentivise partnerships between businesses and research organisations. It reiterated that from 10 December 2026, the Privacy Act will require regulated entities to disclose in their privacy policies how personal information is used in substantially automated decisions affecting individuals’ rights or interests. And it confirmed that the Electoral Integrity Assurance Taskforce had assessed, following the 2025 federal election, that AI did not interfere with election delivery — though it acknowledged AI-generated disinformation posed ongoing risks.

These implementation steps matter because they signal concrete timelines and institutional commitments rather than aspirational policy statements. For compliance professionals, two dates stand out: 5 June (COPC consultation closes) and 10 December (both the COPC registration deadline and the Privacy Act automated decision-making transparency requirements take effect).

Stories

Corrs warns Children’s Online Privacy Code will require “fundamental changes” to online services

Corrs Chambers Westgarth published a comprehensive legal analysis of the OAIC’s Children’s Online Privacy Code exposure draft, warning the Code would represent “a significant shift in the Australian regulatory landscape” for any organisation whose digital products involve children’s personal information. The analysis highlights the Code’s novel “assent” concept for children under 15, its prohibition on coercive consent methods including “confirmshaming,” and the requirement for major technical, operational, and policy changes to achieve compliance. The 60-day public consultation closes 5 June 2026, with the Code due for registration by 10 December 2026.

Source: corrs.com.au

Industry analysts identify Anthropic’s Economic Index data-sharing as the MOU’s most novel feature

SmartCompany’s analysis identified Anthropic’s commitment to share its Economic Index data with the Australian government as the most distinctive element of the 1 April MOU, describing it as “something a bit different” from prior partnerships with OpenAI or Microsoft. The Economic Index tracks how Claude is used across the economy by sector, task type, and labour impact, with initial focus on natural resources, agriculture, healthcare, and financial services. SmartCompany noted this gives government structured visibility into real AI usage patterns but cautioned the data reflects only Anthropic’s user base, offering “a partial view rather than a complete one.”

Source: smartcompany.com.au

Copyright Agency welcomes government’s rejection of text and data mining exception for AI

The Copyright Agency published an immediate reaction to the government’s formal response to the Senate Select Committee on Adopting AI, welcoming the confirmation that Australia will not introduce a text and data mining exception for AI training. The Agency highlighted three priorities being pursued through the Copyright and AI Reference Group (CAIRG): establishing licensing arrangements for AI use of copyright material, improving certainty on copyright for AI-generated material, and exploring a small claims forum for copyright disputes. The government also committed to considering AI’s impacts on the creative sector through the next National Cultural Policy consultations commencing in 2026.

Source: copyright.com.au

Gilbert + Tobin analysis confirms UTP Bill specifically targets AI-powered dark patterns

Gilbert + Tobin published a detailed analysis of the Competition and Consumer Amendment (Unfair Trading Practices) Bill 2026 introduced on 1 April, confirming the Bill’s general prohibition directly captures AI-driven recommendation systems, personalised pricing algorithms, and automated design manipulation. Maximum penalties of AU$50 million per contravention for a body corporate apply, with the Bill set to commence 1 July 2027 if passed. The government has already begun consultations on extending protections to small businesses, and is working with ASIC on whether further steps are needed in the financial services sector. The Senate is not scheduled to debate the Bill until 12–14 May 2026.

Source: gtlaw.com.au

DTA begins hiring to operationalise whole-of-government AI oversight committee

The Digital Transformation Agency is recruiting eight new positions to stand up the promised whole-of-government AI oversight committee, iTnews reports. Roles include a digital governance and risk expert to establish and manage the committee, and a senior AI policy officer. DTA Acting CEO Lucy Poole confirmed the roles are “a direct response to the government’s policy to establish the committee,” which was first announced by Finance Minister Katy Gallagher in November 2025 as part of the APS AI Plan. The committee is scheduled to become operational late 2026 and reach full maturity by early 2027.

Source: itnews.com.au

OAIC launches formal COPC consultation with webinar, roundtables and Regulatory Impact Analysis

The OAIC held a public webinar on 1 April to launch the formal consultation process for the Children’s Online Privacy Code, following the exposure draft’s release on 31 March. The 60-day consultation closes 5 June 2026, with Virtual Roundtables planned between 31 May and 5 June for deeper stakeholder engagement. The OAIC also confirmed it will conduct a Regulatory Impact Analysis — a formal cost-benefit assessment of the Code’s implementation — alongside the public consultation. Written submissions can be directed to [email protected] and may be published on the OAIC website.

Source: oaic.gov.au

DLA Piper analysis says COPC signals tougher regulatory stance on children’s data

DLA Piper’s privacy team published an analysis of the OAIC’s Children’s Online Privacy Code exposure draft, characterising it as signalling “tougher standards” for how organisations handle children’s data. The analysis notes the Code applies on a per-service basis to providers of social media, relevant electronic services, and designated internet services likely to be accessed by children, capturing a broad range of applications including “family photo sharing applications” and “internet-connected baby monitors.” DLA Piper flagged the Code’s alignment with international instruments, particularly the UK’s Age Appropriate Design Code, while noting the Australian version includes novel protections.

Source: privacymatters.dlapiper.com

Startup Daily highlights divergent framing between government and Anthropic on MOU substance

Startup Daily ran both the government’s and Anthropic’s MOU press releases through Claude itself to compare the framing, finding notable divergences. The government version used softer, tentative language (“outlines options,” “exploring investments”) while Anthropic’s framing was more confident. Supply chain security language appeared only in the government release — described as “the most geopolitically significant line” in either document. Startup Daily characterised the AUD$3 million research commitment as modest relative to Anthropic’s scale: “like the boss slapping $50 on the pub counter for Christmas drinks.”

Source: startupdaily.net

Anthropic CEO navigates copyright tensions and geopolitical framing during Canberra visit

Cyber Daily reported that Anthropic CEO Dario Amodei navigated copyright tensions during his meetings with PM Albanese and Treasurer Chalmers at Parliament House, noting that while the company positions itself as the most safety-conscious AI developer, it has previously critiqued Australia’s copyright legislation. Amodei stated he was not there to “try and convince you to change your mind” on copyright. At Parliament House, he warned AI could enable a “panopticon” if used by authoritarian surveillance states and framed AI as a “military competition” where democracies must maintain their edge — comments that came against the backdrop of Anthropic’s dispute with the US Pentagon, which has designated the company a supply-chain risk.

Source: cyberdaily.au

Stay across Australian AI governance

Get the briefing delivered to your inbox every week. No spam, unsubscribe any time.